Privacy Policy
Last updated: August 1, 2026
This policy explains what information cutdown.link collects, why we use it, and the choices available to you. It applies to the cutdown.link website, accounts, short links, QR codes, redirect service, and related communications. The service is operated by Aagee AI Pte Ltd, a company registered in Singapore ("we", "us", or "our"), and its handling of personal data is governed by Singapore law, including the Personal Data Protection Act 2012 (PDPA), where applicable.
Information we collect
Account information
If you create an account, we store your email address, a securely hashed version of your password, account verification status, temporary verification or password-reset tokens, and account creation date. We do not store your password in readable form.
Links and QR codes
We store each destination URL and short code, its creation date, optional start and expiry dates, status, ownership information for account links, and security-blocking information. For an anonymous link, we also create a private statistics key. QR codes are generated from the short link in your browser; the QR image is not stored as a separate account file by us.
Do not put personal, confidential, or secret information in a destination URL. URLs can contain information in their path or query parameters and may be processed by our infrastructure and security providers.
Clicks on short links
When someone follows a cutdown.link short link, we record the short code, time of the request, IP address, and browser user-agent string. We use these records to count clicks, operate and protect the redirect service, investigate abuse, and diagnose reliability problems. Link owners see aggregated click counts for today, the last 7 days, and the last 30 days; they do not receive visitors' IP addresses or user-agent strings through the service.
Website, security, and session data
Our servers and hosting providers may process request information such as IP address, requested page, timestamp, browser details, and diagnostic logs. Signed-in sessions use an essential authentication cookie. Rate limiting may process an IP-based identifier to prevent automated abuse.
If you select "Allow measurement", the website loads Google Tag Manager and LodyCDP. Depending on their configuration, these services may receive device, page, and interaction information and may use cookies or similar browser storage. They do not load if you select "Essential only". These tools help us understand website use and service reliability; they are not used to give link owners information about individual visitors.
When measurement is allowed and you arrive through a campaign link, we may retain campaign parameters such as UTM labels, a Google click identifier, the landing path, and capture time. If you sign up, this attribution may be stored with your account so we can measure verified signups and first managed-link creation rather than treating a page visit as a successful outcome.
Why we use information
- To create, redirect, edit, schedule, pause, expire, and report statistics for links.
- To create and secure accounts and send verification and password-reset messages.
- To detect malicious destinations, spam, fraud, and attempts to bypass service restrictions.
- To maintain, troubleshoot, measure, and improve the service.
- To respond to support, privacy, and abuse requests and comply with applicable law.
We do not sell personal data. We do not use account email addresses for marketing unless we separately ask for permission.
Service providers and disclosures
We use specialist providers to operate the service. They process information only for relevant services:
- Hosting and content delivery providers process website requests and operational logs.
- MongoDB infrastructure stores account, link, click, and security-event records.
- Upstash provides rate limiting and receives the identifier used for a rate-limit check.
- Brevo sends account verification and password-reset email.
- Google Safe Browsing receives destination URLs for malicious-site screening.
- Google Fonts supplies the Sora typeface and receives ordinary font requests such as IP address and browser details.
- Google Tag Manager and LodyCDP support website measurement and monitoring when you allow it.
Providers may process information outside Singapore. We also may disclose information when reasonably necessary to comply with law, respond to valid legal requests, protect people or the service, investigate abuse, or as part of a transfer of the service. We do not disclose personal data to link owners except for the aggregated statistics described above.
Retention
Account and managed-link information is retained while the account or link remains active and afterward where reasonably needed for security, dispute resolution, or legal obligations. Anonymous links and their private statistics remain stored until removed by us or following a valid request. Raw click records, including full IP addresses and browser user-agent strings, are retained for up to 90 days so we can provide recent click statistics, investigate abuse reports, and respond to security incidents. They are then deleted automatically. A link's cumulative click counter may remain after the raw records expire. Operational and security logs are kept only while reasonably needed for troubleshooting, abuse prevention, or legal obligations. The service does not currently offer automatic self-service account deletion; you may request deletion using the address below.
Your choices and requests
You may ask to access or correct personal data associated with you, withdraw consent where processing relies on consent, or request deletion of your account and associated information. Some information may be retained where required for security, legal compliance, or the establishment or defence of claims. You can also use the "Privacy choices" link in the footer to allow or stop non-essential measurement. Essential storage is still used for your saved privacy choice and, if you sign in, authentication. Blocking the essential session cookie will prevent account login from working.
To make a privacy request, contact dpo@cutdown.link. We may need to verify that you control the relevant email address, account, link, or private statistics key before acting on a request.
Security and children
We use reasonable technical and organisational safeguards, but no internet service can guarantee complete security. The service is not directed to children under 13, and we do not knowingly create accounts for them. If you believe a child has provided personal data, contact us so we can investigate and remove it.
Changes and contact
We may update this policy when the service or its data practices change. We will publish the revised policy here and update the date above. For questions, complaints, access or correction requests, or withdrawal of consent, contact our Data Protection Officer at dpo@cutdown.link. General support and abuse reports can be sent to info@cutdown.link.
This policy is intended to describe the service accurately and is not a substitute for advice from a qualified lawyer about obligations that apply to your particular organisation and users.